CVE-2025-0746
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-0746 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting EmbedAI versions 2.1 and below. This issue enables authenticated attackers to inject malicious JavaScript code through the "/embedai/users/show/<SCRIPT>" endpoint by crafting a malicious URL. When an unsuspecting user opens the malicious URL, the malicious JavaScript code is executed, potentially compromising their session or stealing sensitive information. Attackers can use this vulnerability to launch various attacks, including session hijacking, identity theft, and data exfiltration. It is important for EmbedAI users to upgrade to the latest version or implement appropriate XSS protection mechanisms to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.